Summary is AI-generated, newsdesk-reviewed
  • HID introduces Enterprise Attestation in FIDO authenticators for enhanced device trust, compliance.
  • Enterprise Attestation ensures only company-issued passkeys are registered, boosting device traceability.
  • Healthcare and critical sectors benefit from compliance support with auditability and device provenance.

HID has announced the integration of Enterprise Attestation in its suite of FIDO standard-based authenticators, including smart cards and keys.

This capability enables organizations to ensure that only company-issued passkeys are used during registration, verifying the origin of the authenticators prior to credential acceptance. By implementing this, organizations can enhance device trust, gain insights into the source of authenticators, and maintain high-assurance authentication without increasing complexity for users.

User Login Experience

While passkeys effectively tackle phishing threats, enterprises need assurance that the devices generating these credentials are trustworthy and issued by them. According to the FIDO Alliance report on Passkey Deployment in Enterprises, regulatory compliance is a barrier for 20% of organizations adopting passkeys. Enterprise Attestation provides a solution by making device trust and governance explicit and enforceable.

Enterprise Attestation provides a solution by making device trust and governance explicit

Without it, an enterprise might unwittingly register personal authenticators instead of those they distribute and control. This feature verifies the device's issuance by the organization, supplying security teams with necessary governance and traceability without altering user login experiences.

Valid Attestation Data

Embedded into HID’s Crescendo series, which includes FIDO2-certified smart cards and security keys, and compatible with platforms like PingOne, Enterprise Attestation confirms authenticator provenance at passkey registration.

If a device fails to present valid attestation data, enrollment is blocked, adhering to policies without necessitating changes in application workflows or user steps. As part of the FIDO Alliance’s WebAuthn and CTAP specifications, this approach supports standard passkey governance, avoiding proprietary systems or deviations in user experience.

Healthcare and Critical Infrastructure

While this filters unauthorized hardware, it cannot confirm the device's issuance source

Highly regulated sectors such as financial services, healthcare, and critical infrastructure benefit significantly from Enterprise Attestation. This capability assists in compliance with auditing, device provenance, and lifecycle management requirements. Global firms guided by frameworks like the EU's NIS2 Directive, DORA, and Zero Trust principles can utilize this feature to enforce policy at the authenticator level effectively.

To illustrate the practical application of Enterprise Attestation, consider a global retailer restricting passkey registration to specified authenticator models. While this filters unauthorized hardware, it cannot confirm the device's issuance source. 

Enterprise Attestation resolves this by checking for a certificate linking the device to a recognized, company-issued authenticator. Enrollment is blocked if the certificate is absent or unrecognized. If access is granted, the user's login experience remains unchanged, while the organization gains a verifiable and auditable record of each device's registration. HID’s Crescendo authenticators with Enterprise Attestation are now available worldwide.

In case you missed it

Responsible AI Adoption Starts With Governance
Responsible AI Adoption Starts With Governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation
Solink's AI Agents Boost Efficiency Of Existing Infrastructure With Automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...

rf IDEAS Supports Gallagher Badge In Apple Wallet
rf IDEAS Supports Gallagher Badge In Apple Wallet

rf IDEAS, a global manufacturer of RFID credential readers, announces that its WAVE ID® readers support Gallagher Employee Badge in Apple Wallet, expanding the range of credent...